When the CA URL is correct, and the fingerprint does not match, the output of step ca bootstrap is confusing:
$ step ca bootstrap --ca-url https://ca.example.com --fingerprint abc1230
The requested resource could not be found. Please see the certificate authority logs for more info.
Re-run with STEPDEBUG=1 for more info.
It would be nice here if the client could say that the cert fingerprint doesn't match.